CVE-2023-6446Dwbooster · Calculated_fields_form
Vulnerability data via NVD (ingested)
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2023-6446http.html:"/wp-content/plugins/calculated-fields-form/"product:"Dwbooster Calculated Fields Form"http.html:"Calculated Fields Form"More intel sources (5)
vuln:CVE-2023-6446vulnerabilities.cve_id: CVE-2023-6446CVE-2023-6446CVE-2023-6446"CVE-2023-6446" exploit -site:nvd.nist.gov